ok HJT renamed and log follows then the combofix.txt……
Logfile of HijackThis v1.99.1
Scan saved at 11:59:48 AM, on 17/11/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5730.0011)
Running processes:
C:\WINXP\System32\smss.exe
C:\WINXP\system32\winlogon.exe
C:\WINXP\system32\services.exe
C:\WINXP\system32\lsass.exe
C:\WINXP\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINXP\System32\svchost.exe
C:\WINXP\system32\spoolsv.exe
C:\WINXP\Explorer.EXE
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\Program Files\Microsoft IntelliType Pro\type32.exe
C:\Program Files\Microsoft IntelliPoint\point32.exe
C:\Program Files\Java\jre1.5.0_09\bin\jusched.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\WINXP\system32\rundll32.exe
C:\Program Files\SPYWAREfighter\spftray.exe
C:\WINXP\system32\ctfmon.exe
C:\WINXP\system32\crypserv.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINXP\system32\svchost.exe
C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe
C:\Program Files\SPYWAREfighter\spfprc.exe
C:\WINXP\system32\wuauclt.exe
C:\download central\search.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ycomp/def…/search/ie.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ie/defaul…//www.yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://us.rd.yahoo.com/customize/ie/defaul…//www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaul…rch/search.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ie/defaul…//www.yahoo.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
http://go.microsoft.com/fwlink/?LinkId=566…k/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://us.rd.yahoo.com/customize/ie/defaul…//www.yahoo.com
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn2\yt.dll
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn2\yt.dll
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
O2 - BHO: (no name) - {CFE9E8A8-38C0-4EF8-AEC2-5035EFE81030} - C:\WINXP\system32\ljjhefd.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn2\yt.dll
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [type32] "C:\Program Files\Microsoft IntelliType Pro\type32.exe"
O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\point32.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_09\bin\jusched.exe"
O4 - HKLM\..\Run: [CTDrive] rundll32.exe C:\WINXP\system32\drvmuw.dll,startup
O4 - HKLM\..\Run: [gdxzwo.dll] C:\WINXP\system32\rundll32.exe C:\WINXP\system32\gdxzwo.dll,fkwligg
O4 - HKLM\..\Run: [spywarefighterguard] C:\Program Files\SPYWAREfighter\spftray.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINXP\system32\ctfmon.exe
O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~1\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycmap.htm
O8 - Extra context menu item: Yahoo! &SMS - file:///C:\Program Files\Yahoo!\Common/ycsms.htm
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~1\OFFICE11\REFIEBAR.DLL
O11 - Options group: [INTERNATIONAL] International*
O12 - Plugin for .pdf: C:\Program Files\Internet Explorer\PLUGINS\nppdf32.dll
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?LinkID=39204
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) -
http://update.microsoft.com/microsoftupdat…b?1147225346055
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMesse…pDownloader.cab
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: ljjhefd - C:\WINXP\SYSTEM32\ljjhefd.dll
O20 - Winlogon Notify: WgaLogon - C:\WINXP\SYSTEM32\WgaLogon.dll
O20 - Winlogon Notify: WRNotifier - C:\WINXP\SYSTEM32\WRLogonNTF.dll
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O23 - Service: Crypkey License - Kenonic Controls Ltd. - C:\WINXP\SYSTEM32\crypserv.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: SPYWAREfighterRP - SpamFighter APS - C:\Program Files\SPYWAREfighter\spfprc.exe
O23 - Service: Webroot Spy Sweeper Engine (svcWRSSSDK) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe
Sharyn - 06-11-17 11:38:34.47 Service Pack 2
ComboFix 06.11.9 - Running from: "C:\Documents and Settings\Sharyn\Desktop"
(((((((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
C:\WINXP\system32\ishost.exe
C:\WINXP\system32\ismini.exe
C:\WINXP\system32\components
C:\Program Files\Common Files\{151413F4-01D4-3081-0825-99072819003d}
C:\Program Files\Common Files\{351413F4-01D4-3081-0825-99072819003d}
C:\Program Files\Common Files\{151413F4-01D2-3081-0825-99072819003d}
C:\Program Files\Common Files\{351413F4-01D2-3081-0825-99072819003d}
~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ Purity ~ ~ ~ ~ ~ ~ ~ ~~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~
Folders Quarantined:
C:\QooBox\Purity\WINXP\CROSOF~1.NET
C:\QooBox\Purity\WINXP\ECURIT~1
C:\QooBox\Purity\WINXP\SSEMBL~1
C:\QooBox\Purity\WINXP\APPATC~1
C:\QooBox\Purity\WINXP\system32\MCROSO~1
C:\QooBox\Purity\WINXP\system32\ICROSO~1
C:\QooBox\Purity\WINXP\system32\CROSOF~1.NET
C:\QooBox\Purity\WINXP\system32\YSTEM3~1
C:\QooBox\Purity\WINXP\system32\SEMBLY~1
C:\QooBox\Purity\Program Files\MCROSO~1.NET
C:\QooBox\Purity\Program Files\SSTEM3~1
C:\QooBox\Purity\Program Files\YMBOLS~1
C:\QooBox\Purity\Program Files\SMBOLS~1
C:\QooBox\Purity\Program Files\Common Files\RACLE~1
C:\QooBox\Purity\Program Files\Common Files\TSKS~1
C:\QooBox\Purity\Program Files\Common Files\ASKS~1
C:\QooBox\Purity\Program Files\Common Files\SKS~1
C:\QooBox\Purity\Program Files\Common Files\SSTEM3~1
C:\QooBox\Purity\Program Files\Common Files\YMBOLS~1
C:\QooBox\Purity\Program Files\Common Files\FNTS~1
C:\QooBox\Purity\Program Files\Common Files\PPPATC~1
C:\QooBox\Purity\Program Files\Common Files\APPATC~1
C:\QooBox\Purity\Documents and Settings\Sharyn\Application Data\CROSOF~1.NET
C:\QooBox\Purity\Documents and Settings\Sharyn\Application Data\STEM32~1
C:\QooBox\Purity\Documents and Settings\Sharyn\Application Data\SEMBLY~1
C:\QooBox\Purity\Documents and Settings\Sharyn\Application Data\ASEMBL~1
((((((((((((((((((((((((((((((( Files Created from 2006-10-17 to 2006-11-17 ))))))))))))))))))))))))))))))))))
2006-11-16 12:46 24,576 –a—— C:\WINXP\system32\VundoFixSVC.exe
2006-11-14 23:17 3,968 –a—— C:\WINXP\system32\drivers\avgclean.sys
2006-11-14 23:17 18,240 –a—— C:\WINXP\system32\drivers\avgmfx86.sys
2006-11-14 14:27 94,208 –a—— C:\WINXP\system32\gdxzwo.dll
2006-11-14 14:27 71,680 –a—— C:\WINXP\system32\ffmtkbg.dll
2006-11-14 14:26 40,973 —hs—- C:\WINXP\system32\iifghge.dll
2006-11-14 05:07 692,276 –a—— C:\WINXP\system32\ljjhh.dll
2006-11-14 05:06 692,276 –a—— C:\WINXP\system32\jkkjk.dll
2006-11-14 05:02 692,276 –a—— C:\WINXP\system32\hgddd.dll
2006-11-14 05:01 692,276 –a—— C:\WINXP\system32\opnkl.dll
2006-11-14 04:57 692,276 –a—— C:\WINXP\system32\iifef.dll
2006-11-14 04:56 692,276 –a—— C:\WINXP\system32\tuvuv.dll
2006-11-14 04:51 692,276 –a—— C:\WINXP\system32\hgdcd.dll
2006-11-14 04:50 692,276 –a—— C:\WINXP\system32\nnlki.dll
2006-11-14 04:44 692,276 –a—— C:\WINXP\system32\gebaw.dll
2006-11-14 04:43 692,276 –a—— C:\WINXP\system32\hggdb.dll
2006-11-14 04:36 692,276 –a—— C:\WINXP\system32\urqrp.dll
2006-11-14 04:35 692,276 –a—— C:\WINXP\system32\fccya.dll
2006-11-14 04:29 692,276 –a—— C:\WINXP\system32\khhed.dll
2006-11-14 04:27 692,276 –a—— C:\WINXP\system32\awttt.dll
2006-11-14 04:21 692,276 –a—— C:\WINXP\system32\efcab.dll
2006-11-14 04:19 692,276 –a—— C:\WINXP\system32\jkkig.dll
2006-11-14 04:13 692,276 –a—— C:\WINXP\system32\sstqn.dll
2006-11-14 04:11 692,276 –a—— C:\WINXP\system32\ddaba.dll
2006-11-14 04:05 692,276 –a—— C:\WINXP\system32\nnnno.dll
2006-11-14 04:03 692,276 –a—— C:\WINXP\system32\fcyaw.dll
2006-11-14 03:57 692,276 –a—— C:\WINXP\system32\hgdbb.dll
2006-11-14 03:55 692,276 –a—— C:\WINXP\system32\byxya.dll
2006-11-14 03:50 692,276 –a—— C:\WINXP\system32\pmklk.dll
2006-11-14 03:48 692,276 –a—— C:\WINXP\system32\yayww.dll
2006-11-14 03:43 692,276 –a—— C:\WINXP\system32\tusss.dll
2006-11-14 03:42 692,276 –a—— C:\WINXP\system32\byvtr.dll
2006-11-14 03:38 692,276 –a—— C:\WINXP\system32\nnlkk.dll
2006-11-14 03:37 692,276 –a—— C:\WINXP\system32\wvwwx.dll
2006-11-14 03:33 692,276 –a—— C:\WINXP\system32\cbxyy.dll
2006-11-14 03:32 692,276 –a—— C:\WINXP\system32\gebcc.dll
2006-11-14 03:27 692,276 –a—— C:\WINXP\system32\geefe.dll
2006-11-14 03:26 692,276 –a—— C:\WINXP\system32\fcyww.dll
2006-11-14 03:22 692,276 –a—— C:\WINXP\system32\wvuuu.dll
2006-11-14 03:21 692,276 –a—— C:\WINXP\system32\gebxx.dll
2006-11-14 03:17 692,276 –a—— C:\WINXP\system32\hggff.dll
2006-11-14 03:16 692,276 –a—— C:\WINXP\system32\khhii.dll
2006-11-14 03:11 692,276 –a—— C:\WINXP\system32\jkkjg.dll
2006-11-14 03:10 692,276 –a—— C:\WINXP\system32\ssqnk.dll
2006-11-14 03:06 692,276 –a—— C:\WINXP\system32\cbayx.dll
2006-11-14 03:05 692,276 –a—— C:\WINXP\system32\pmnkj.dll
2006-11-14 03:01 692,276 –a—— C:\WINXP\system32\nnnmm.dll
2006-11-14 03:00 692,276 –a—— C:\WINXP\system32\rqroo.dll
2006-11-14 02:55 692,276 –a—— C:\WINXP\system32\fcywx.dll
2006-11-14 02:54 692,276 –a—— C:\WINXP\system32\cbxuv.dll
2006-11-14 02:50 692,276 –a—— C:\WINXP\system32\wvuvt.dll
2006-11-14 02:49 692,276 –a—— C:\WINXP\system32\efeec.dll
2006-11-14 02:44 692,276 –a—— C:\WINXP\system32\vtutu.dll
2006-11-14 02:43 692,276 –a—— C:\WINXP\system32\vturq.dll
2006-11-14 02:38 692,276 –a—— C:\WINXP\system32\qomjg.dll
2006-11-14 00:20 77,824 –a—— C:\WINXP\system32\cfltygd.dll
2006-11-14 00:12 59,392 –a—— C:\WINXP\system32\drvmuw.dll
2006-11-14 00:12 40,973 —hs—- C:\WINXP\system32\ljjhefd.dll
2006-11-09 03:07 197,120 –a—— C:\WINXP\system32\3-D_Mardi_Gras_Teddy_Bears_DemoESD.scr
2006-11-04 14:14 1,245,696 –a—— C:\WINXP\system32\msxml4.dll
2006-10-17 13:33 6,049,280 ——— C:\WINXP\system32\ieframe.dll
2006-10-17 13:33 50,688 ——— C:\WINXP\system32\msfeedsbs.dll
2006-10-17 13:33 458,752 ——— C:\WINXP\system32\msfeeds.dll
2006-10-17 13:33 180,736 ——— C:\WINXP\system32\ieui.dll
2006-10-17 13:05 206,336 ——— C:\WINXP\system32\WinFXDocObj.exe
2006-10-17 12:58 61,952 ——— C:\WINXP\system32\icardie.dll
2006-10-17 12:58 12,288 ——— C:\WINXP\system32\msfeedssync.exe
2006-10-17 12:57 266,752 ——— C:\WINXP\system32\iertutil.dll
2006-10-17 12:27 380,928 ——— C:\WINXP\system32\ieapfltr.dll
(((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))))
2006-11-16 16:56 ——– d——– C:\Program Files\MSXML 4.0
2006-11-15 03:39 ——– d——– C:\Program Files\Common Files\Application
2006-11-15 03:38 ——– d——– C:\Program Files\SPYWAREfighter
2006-11-14 23:17 816672 –a—— C:\WINXP\system32\drivers\avg7core.sys
2006-11-14 23:17 4960 –a—— C:\WINXP\system32\drivers\avgtdi.sys
2006-11-14 23:17 4224 –a—— C:\WINXP\system32\drivers\avg7rsw.sys
2006-11-14 23:17 28416 –a—— C:\WINXP\system32\drivers\avg7rsxp.sys
2006-11-14 20:10 ——– d——– C:\Program Files\Enigma Software Group
2006-11-09 03:00 ——– d——– C:\Program Files\Screensavers.com
2006-10-23 15:49 ——– d——– C:\Program Files\Oberon Media
2006-10-17 13:33 413696 –a—— C:\WINXP\system32\vbscript.dll
2006-10-17 13:33 231424 –a—— C:\WINXP\system32\webcheck.dll
2006-10-17 13:33 156160 –a—— C:\WINXP\system32\msls31.dll
2006-10-17 13:06 78336 –a—— C:\WINXP\system32\ieencode.dll
2006-10-17 13:05 40960 –a—— C:\WINXP\system32\licmgr10.dll
2006-10-17 13:05 105984 –a—— C:\WINXP\system32\url.dll
2006-10-17 13:04 101376 –a—— C:\WINXP\system32\occache.dll
2006-10-17 13:03 17408 –a—— C:\WINXP\system32\corpol.dll
2006-10-17 13:01 71680 –a—— C:\WINXP\system32\admparse.dll
2006-10-17 13:01 55296 –a—— C:\WINXP\system32\iesetup.dll
2006-10-17 13:01 382976 –a—— C:\WINXP\system32\iedkcs32.dll
2006-10-17 13:01 229376 –a—— C:\WINXP\system32\ieaksie.dll
2006-10-17 13:01 152064 –a—— C:\WINXP\system32\ieakeng.dll
2006-10-17 13:01 13312 –a—— C:\WINXP\system32\ieudinit.exe
2006-10-17 13:00 54784 –a—— C:\WINXP\system32\ie4uinit.exe
2006-10-17 13:00 43008 –a—— C:\WINXP\system32\iernonce.dll
2006-10-17 13:00 123904 –a—— C:\WINXP\system32\advpack.dll
2006-10-17 12:57 36352 –a—— C:\WINXP\system32\imgutil.dll
2006-10-17 12:56 45568 –a—— C:\WINXP\system32\mshta.exe
2006-10-17 12:28 48128 –a—— C:\WINXP\system32\mshtmler.dll
2006-10-17 12:23 161792 –a—— C:\WINXP\system32\ieakui.dll
2006-10-13 23:35 142336 –a—— C:\WINXP\system32\nwprovau.dll
2006-09-25 23:58 545280 –a—— C:\WINXP\flashax.exe
2006-09-25 23:58 12288 –a—— C:\WINXP\impborl.dll
2006-09-21 02:49 ——– d——– C:\Program Files\BadgeHelp
2006-09-13 15:01 1084416 –a—— C:\WINXP\system32\msxml3.dll
2006-09-06 17:43 22752 –a—— C:\WINXP\system32\spupdsvc.exe
2006-08-26 01:45 617472 –a—— C:\WINXP\system32\comctl32.dll
2006-08-21 22:21 16896 –a—— C:\WINXP\system32\fltlib.dll
2006-08-21 19:14 23040 –a—— C:\WINXP\system32\fltMc.exe
2006-08-17 23:28 721920 –a—— C:\WINXP\system32\lsasrv.dll
2006-08-17 23:28 132096 –a—— C:\WINXP\system32\wkssvc.dll
(((((((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))
*Note* empty entries are not shown
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run]
"ctfmon.exe"="C:\\WINXP\\system32\\ctfmon.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]
"AVG7_CC"="C:\\PROGRA~1\\Grisoft\\AVGFRE~1\\avgcc.exe /STARTUP"
"type32"="\"C:\\Program Files\\Microsoft IntelliType Pro\\type32.exe\""
"IntelliPoint"="\"C:\\Program Files\\Microsoft IntelliPoint\\point32.exe\""
"SunJavaUpdateSched"="\"C:\\Program Files\\Java\\jre1.5.0_09\\bin\\jusched.exe\""
"CTDrive"="rundll32.exe C:\\WINXP\\system32\\drvmuw.dll,startup"
"gdxzwo.dll"="C:\\WINXP\\system32\\rundll32.exe C:\\WINXP\\system32\\gdxzwo.dll,fkwligg"
"spywarefighterguard"="C:\\Program Files\\SPYWAREfighter\\spftray.exe"
@=""
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\IMAIL]
"Installed"="1"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MAPI]
"NoChange"="1"
"Installed"="1"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MSFS]
"Installed"="1"
[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components]
"DeskHtmlVersion"=dword:00000110
"DeskHtmlMinorVersion"=dword:00000005
"Settings"=dword:00000001
"GeneralFlags"=dword:00000001
[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components\0]
"Source"="About:Home"
"SubscribedURL"="About:Home"
"FriendlyName"="My Current Home Page"
"Flags"=dword:00000002
"Position"=hex:2c,00,00,00,70,00,00,00,00,00,00,00,90,03,00,00,de,02,00,00,00,\
00,00,00,01,00,00,00,01,00,00,00,01,00,00,00,00,00,00,00,00,00,00,00
"CurrentState"=hex:04,00,00,40
"OriginalStateInfo"=hex:18,00,00,00,a0,00,00,00,00,00,00,00,80,02,00,00,36,02,\
00,00,04,00,00,40
"RestoredStateInfo"=hex:18,00,00,00,a0,00,00,00,00,00,00,00,80,02,00,00,36,02,\
00,00,01,00,00,00
[HKEY_USERS\.default\software\microsoft\windows\currentversion\run]
"CTFMON.EXE"="C:\\WINXP\\system32\\CTFMON.EXE"
"AVG7_Run"="C:\\PROGRA~1\\Grisoft\\AVGFRE~1\\avgw.exe /RUNONCE"
[HKEY_USERS\s-1-5-18\software\microsoft\windows\currentversion\run]
"CTFMON.EXE"="C:\\WINXP\\system32\\CTFMON.EXE"
"AVG7_Run"="C:\\PROGRA~1\\Grisoft\\AVGFRE~1\\avgw.exe /RUNONCE"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\sharedtaskscheduler]
"{438755C2-A8BA-11D1-B96B-00A0C90312E1}"="Browseui preloader"
"{8C7461EF-2B13-11d2-BE35-3078302C2030}"="Component Categories cache daemon"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{AEB6717E-7E19-11d0-97EE-00C04FD91972}"=""
"{091EB208-39DD-417D-A5DD-7E2C2D8FB9CB}"="Microsoft AntiMalware ShellExecuteHook"
"{CFE9E8A8-38C0-4EF8-AEC2-5035EFE81030}"=""
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer\Run]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"dontdisplaylastusername"=dword:00000000
"legalnoticecaption"=""
"legalnoticetext"=""
"shutdownwithoutlogon"=dword:00000001
"undockwithoutlogon"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer\run]
"ishost.exe"="ishost.exe"
[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091
[HKEY_USERS\s-1-5-18\software\microsoft\windows\currentversion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\shellserviceobjectdelayload]
"PostBootReminder"="{7849596a-48ea-486e-8937-a2a3009f31a9}"
"CDBurn"="{fbeb8a05-beee-4442-804e-409d6c4515e9}"
"WebCheck"="{E6FB5E20-DE35-11CF-9C87-00AA005127ED}"
"SysTray"="{35CEC8A3-2BE6-11D2-8773-92E220524153}"
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\ljjhefd
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"="msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll"
Contents of the 'Scheduled Tasks' folder
C:\WINXP\tasks\wrSpySweeper20060716175033.job
C:\WINXP\tasks\MP Scheduled Scan.job
Completion time: 06-11-17 11:44:50.50
C:\ComboFix.txt … 06-11-17 11:44
and before I forget thank you So much for your time and effort in helping me